CVE-2017-8391: Medium severity broadcom client automation vulnerability
The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive information by reading this file after operating system installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8391?
CVE-2017-8391 is classified as a medium severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2017-8391?
To resolve CVE-2017-8391, update to a version of CA Client Automation that does not expose encrypted passwords in local files.
What are the affected versions of CA Client Automation for CVE-2017-8391?
The affected versions of CA Client Automation are r12.9, r14.0, and r14.0 SP1.
Can local users exploit CVE-2017-8391?
Yes, local users can exploit CVE-2017-8391 by reading the readable local file that contains the encrypted password.
Is CVE-2017-8391 relevant to all operating systems?
CVE-2017-8391 specifically affects CA Client Automation on Linux and is not relevant to Windows systems.